CVE-2014-9972NULL Pointer Dereference in INC Snapdragon Mobile

Severity
9.8CRITICALNVD
EPSS
0.2%
top 52.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 18
Latest updateMay 14

Description

In all Qualcomm products with Android releases from CAF using the Linux kernel, disabling asserts can potentially cause a NULL pointer dereference during an out-of-memory condition.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

CVEListV5qualcomm_inc/snapdragon_mobileSD 400, SD 410/12, SD 615/16/SD 415, SD 800, MDM9615, MDM9625, MDM9635M

🔴Vulnerability Details

1
GHSA
GHSA-c68g-874g-p8wh: In all Qualcomm products with Android releases from CAF using the Linux kernel, disabling asserts can potentially cause a NULL pointer dereference dur2022-05-14

📋Vendor Advisories

1
Android
CVE-2014-9972: Closed-source component2018-04-01